Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-XSS-Protection
X-Frame-Options
Strict-Transport-Security
CF-RAY
Age
X-Cache
P3P
Expect-CT
X-AspNet-Version
Content-Language
X-Pingback
Upgrade
Via
X-UA-Compatible
Access-Control-Allow-Origin
Content-Security-Policy
X-FRAME-OPTIONS
X-Varnish
X-Cacheable
Referrer-Policy
X-Adblock-Key
X-Request-Id
X-Check
X-Generator
X-Template
X-Language
X-Drupal-Cache
X-Buckets
Alt-Svc
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-Ac
X-Hacker
X-Cache-Hits
X-AspNetMvc-Version
Host-Header
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-PrivacyLevel
X-Shopify-Stage
X-Dc
X-Alternate-Cache-Key
X-Xss-Protection
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Served-By
X-Powered-By-Plesk
X-Via
X-Runtime
MS-Author-Via
X-Contextid
Access-Control-Allow-Headers
X-Amz-Cf-Id
X-IPLB-Instance
X-Powered-CMS
Access-Control-Allow-Methods
P3p
X-UA-Device
Content-Location
X-Timer
X-ServedBy
X-PC-Key
X-PC-AppVer
X-PC-Hit
Status
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PC-Date
X-PC-Host
CF-Cache-Status
Cartoon
X-Iinfo
X-Rid
Access-Control-Allow-Credentials
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
Powered-By
X-Seen-By
X-Wix-Request-Id
X-WPE-Loopback-Upstream-Addr
X-Ua-Compatible
X-Mod-Pagespeed
X-Cache-Status
Content-Encoding
X-Tumblr-Pixel-1
X-CST
X-Backend
X-Cache-Enabled
X-Endurance-Cache-Level
X-Tumblr-Pixel-2
X-Logged-In
X-Host
X-Drupal-Dynamic-Cache
X-Server
X-Cache-Hit
X-Port
X-CDN
X-DIS-Request-ID
X-Server-Powered-By
X-Request-ID
Keep-Alive
X-Accel-Version
X-Nginx-Cache-Status
X-Turbo-Charged-By
X-Robots-Tag
X-LiteSpeed-Cache
X-Proxy-Cache
X-Tumblr-Pixel-3
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Allow
X-Page-Speed
X-Content-Digest
X-Content-Powered-By
Content-Security-Policy-Report-Only
X-AH-Environment
Request-Context
X-Rack-Cache
X-GitHub-Request-Id
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Type
X-Pad
X-Varnish-Cache
Access-Control-Expose-Headers
SPRequestGuid
X-MS-InvokeApp
X-SharePointHealthScore
X-Hits
X-Request-Country
MicrosoftSharePointTeamServices
X-XRDS-Location
X-Content-Security-Policy
X-Newrelic-App-Data
Edge-Control
X-Amz-Request-Id
X-Amz-Id-2
X-Webcom-Cache-Status
X-BC-Stapler
Timing-Allow-Origin
X-Trace
Cf-Railgun
X-Node
Request-Id
Edge-Cache-Tag
X-HS-Cache-Config
X-Tumblr-Pixel-4
X-HS-Content-Id
X-FullPageCaching
Charset
X-HOST
WP-Super-Cache
X-CF-Powered-By
SPIisLatency
SPRequestDuration
X-INKT-SITE
X-INKT-URI
Access-Control-Max-Age
X-Backend-Server
X-Cache-Lookup
X-Fastly-Request-ID
X-PHP-Backend
X-Servedby
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Swift-SaveTime
X-HS-Combine-CSS
EagleId
X-Edge-Cache
X-Edge-Cache-Key
Grace
X-Cnection
MicrosoftOfficeWebServer
X-CDN-Pop-IP
X-CDN-Pop
X-SS-Conf
X-SS-Location
Composed-By
X-Safe-Firewall
Served-By
X-Device
X-SERVER
X-Pc-Appver
X-Pc-Key
X-Pc-Hit
X-Hyper-Cache
X-Spip-Cache
Front-End-Https
X-Pc-Host
Surrogate-Control
X-Pc-Date
Liferay-Portal
X-VCache
X-DDC-Arch-Trace
X-LiteSpeed-Cache-Control
X-Dw-Request-Base-Id
X-Firenze-Processing-Times
Rating
X-RateLimit-Remaining
X-Died
X-Tumblr-Pixel-5
X-RateLimit-Limit
X-DNS-Prefetch-Control
X-Loop
X-Server-Name
X-TNCMS
X-RateLimit-Reset
X-OneAgent-JS-Injection
X-Vtex-Processado-Em
X-Cloud-Trace-Context
X-Cluster-Node
X-FB-Debug
X-ServerName
X-Jimdo-Instance
X-Jimdo-Wid
X-Middleton-Display
X-NF-Request-ID
Display
Feature-Policy
X-Sol
X-Kinsta-Cache
X-Debug-Info
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-HeyJason
X-Clacks-Overhead
X-Tumblr-Content-Rating
X-Original-Date
X-WebKit-CSP
X-StackifyID
Xkey
X-Middleton-Response
Response
P-WS
P-LB
X-Acc-Exp
Content-Style-Type
Refresh
Public-Key-Pins
X-Ruxit-JS-Agent
X-XN-Trace-Token
X-Frame-Option
X-XN-XNHTML
Content-Script-Type
X-Age
X-DynaTrace-JS-Agent
X-Magento-Tags
X-Edge-Location
X-Cdn
X-Amz-Version-Id
X-Px
X-FORWARDED-FOR
X-Hostname
Fpc-Cache-Id
X-N-OperationId
X-User-Agent
PageSpeed
X-LW-Cache
X-Tumblr-Pixel-6
X-Zen-Fury
X-Goog-Hash
WPX
X-Cached
X-Cache-Config
X-Handled-By
X-Generated-By
X-Source
X-MiniProfiler-Ids
Retry-After
X-Topify-Platform
X-ARC
X-Outils-CS
X-Webserver
Rt-Fastcgi-Cache
Powered
Dmn
X-B-Cache
X-URL
X-Loopia-Node
Imagetoolbar
X-Vtex-Processed-At
X-VTEX-Janus-Router-Backend-App
No
X-LBLID
X-Powered-By-VTEX-Janus-ApiCache
X-CacheServer
X-VTEX-Cache-Status-Janus-ApiCache
ServedBy
X-Vtex-Remote-Cache
X-Platform-Server
X-Magento-Cache-Debug
X-From
X-CMS-Version
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Request-Time
X-Goog-Metageneration
X-Platform-Router
X-Platform-Processor
Access-Control-Request-Method
X-Platform-Cluster
X-Goog-Generation
X-Goog-Storage-Class
Fastcgi-Cache
TCN
X-ET-API-ORIGIN
X-URLSCHEME
X-ET-API-ROOT
X-ET-API-VERSION
X-Engine
X-DynaTrace
X-Cache-Key
Cache-Provider
X-EdgeConnect-Origin-MEX-Latency
Fhost
X-Url
Pagespeed
X-Msg-2-Log
X-Accel-Expires
X-Passed-To
X-Passed-To-BeforeDispatch
X-Actual-URL
X-Upstream
X-Passed-To-DLL
Public-Key-Pins-Report-Only
X-PhApp
X-Original-Request
X-Cached-By
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Returned-From
X-EdgeConnect-MidMile-RTT
X-Passed-To-PostProcessResponse
Host
X-RESOURCE
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Version
X-Varnish-HitMiss
X-Varnish-Count
X-Stale
X-Varnish-Cache-Hits
X-Ezoic-Cdn
X-Dealeron-Original-Url
X-Dispatcher
X-Signature
X-AspNetWebPages-Version
X-DealerOn
X-SRCache-Store-Status
X-Dealeron-Backend
X-SRCache-Fetch-Status
X-Varnish-TTL
X-Cache-Info
X-Application-Context
X-Location-Id
X-Response-Time
Alternate-Protocol
X-Server-ID
Last-Published
X-Sapient
X-Developer
X-Platform
Warning
X-Art-Request-Id
X-F-Cache
X-Content-Options
X-Cache-Tags
X-Varnish-Host
X-HS-Content-Campaign-Id
Arr-Disable-Session-Affinity
X-Microcachable
X-NWS-LOG-UUID
DynaTrace
X-Platform-Cache
X-Cache-Rule
X-Magento-Cache-Control
X-S
X-Shop-Id
X-Defender
Origin
X-Device-Type
X-Hosted-By
X-Correlation-ID
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Whom
X-SO
X-BS
X-I-Sp
X-Rnd
X-Guploader-Uploadid
Powered-By-ChinaCache
X-Environment
X-Umbraco-Version
X-Supported-By
X-Route-Server
X-Cache-Age
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-I
X-Helper-Autoassign-All
X-Cache-2
X-Forwarded-For
X-Varnish-RemainingTTL
X-Varnish-Seen-By
X-Translation
X-Powered-By-360WZB
X-Microcache-Status
Content-Disposition
X-Vcap-Request-Id
X-Gamma-Serve
Cache-Key
X-Varnish-GracePeriod
X-Cache-TTL
X-Cache-IO
X-Via-JSL
Product
S-Cnection
X-NetCat-Version
X-Micro-Cache
X-Powered-By-VelaWeb
Generator
X-VARITI-CCR
SN
Version
CF-Worker-Version
X-Gateway-Cache-Key
WZWS-RAY
X-Dns-Prefetch-Control
X-App-Status
X-Akam-SW-Version
Server-Timing
X-Gateway-Cache-Status
Service-Worker-Allowed
X-Lambda-Id
X-Gateway-Skip-Cache
X-Cache-Server
Wsr-Cache
X-Instart-Request-ID
X-Hypernode
X-TransIP-Balancer
Surrogate-Key
X-Esi
X-Server-Upstream
Content-Hash
X-Abgroup
X-Cache-Namespace
X-Cache-Type
X-TransIP-Backend
Cneonction
X-Sucuri-ID
X-Nginx-Cache
X-Track
USPLoggingUUID
X-Fastcgi-Cache
X-Cache-Debug
Edge-Control-Message
X-Client-IP
X-Debug
X-SSL-Cipher
X-CSRF-Protection
Https
X-App-Hosting
X-Correlation-Id
SSPAppContext
X-ATG-Version
X-ORACLE-DMS-ECID
X-Cache-Lifetime
X-ORACLE-DMS-RID
X-Nf-Srv-Version
Akamai-IP
X-Expires-Orig
X-Now-Id
X-SSL-Protocol
X-Hostinger-Datacenter
X-PERF
X-Matrix-Server
X-Varnish-Age
X-Hostinger-Node
X-Sucuri-Cache
X-Matrix-Proxy
X-ApacheServer
Page-Completion-Status
X-Last-Modified
X-SDS
X-Rocket-Nginx-Serving-Static
X-Cache-Operation
NnCoection
X-Drupal-Cache-Tags
X-Cache-Control-Orig
X-HW
X-Firenze-Processing-Time
X-SRV
X-Amz-Meta-S3cmd-Attrs
X-Director
X-Geo-Country
Strikingly-Cached-Version
Strikingly-Cache-Region
Strikingly-Cached
X-GUploader-UploadID
MIME-Version
Contao-Page-Layout
Nodo
Author
X-Cache-Level
X-Rq
X-Daa-Tunnel
X-Drupal-Cache-Contexts
Srv
X-LB
X-SV-Pid
X-SV-Nginx-Duration
X-SV-FromDBCache
X-SV-Duration
X-SV-Edge
X-SV-CreatedAt
X-Vhost
AMF-Ver
X-Flow-Powered
X-Cache-Engine
X-SV-Expires
X-Edge-IP
X-Locale
X-Server-Id
X-SV-CacheTags
X-SV-Cacheable
X-Pressidium-NinukisWP-Ver
X-Rocket-Nginx-Bypass
RTSS
X-Cache-Device-Type
X-Duration
Section-Io-Id
X-N
Cache-Tags
X-FTR-Request-ID
X-Powered-By-VTEX-Janus-Edge
X-Ttl
X-ID
X-Generated
X-Recruiting
X-Empowered-By
X-Forwarded-Proto
X-Env
X-SSLUpstream
W
Cache
Content-MD5
Server-Name
X-Url-Base
Proxy-Connection
X-IsCacheURL
X-PwB-Node
FAI-W-FLOW
PICS-Label
X-Varnish-Cacheable
X-NoCache
X-Dynamic-Cache
ServerName
X-SSLProxy
X-Akamai-Device-Model
X-Akamai-Device-Characteristics
Dtk-Cache-Check-0
X-TransIP-Reserved
X-TTL
X-CJ-Soft
X-Content-Type-Option
X-Revision
X-UPSTREAM
X-TTFB
X-Page-Cache
X-SmugMug-Hiring
X-TTFB-L
X-Cache-TTL-Remaining
Lsrequestid
X-SmugMug-Values
Smug-CDN
Server-Info
Local-Info
X-CacheFROM
X-Trace-Id
X-Real-Server
Frame-Options
Pool
X-ACMCache
X-Disney-Akamai-Rule
X-CACHE-TTL
X-Speed-Cache
Accept-CH
X-Adobe-Loc
Location
X-PF-Uncompressing
X-Middleware-Start
X-Adobe-Content
Content-Transfer-Encoding
X-Cache-PageType
X-Cache-Fix
AC-ELC
X-Front
X-Speed-Cache-Key
Src-Update
Update-Time
S
X-Varnish-Url
X-Varnish-IP
X-FW
X-V
Pv
X-SRCache-Key
X-Nginx-Dummy
X-Framework
X-Proxy
X-Content-Age
X-Now-Cache
X-WR-Flags
Front
CDN-Cache
EagleEye-TraceId
Req-Id
X-NginX-Cache
Content_type
Identity
Ufe-Result
Ohc-File-Size
X-Dispatch
X-Litespeed-Cache-Control
Pf.Web.Request.Id
X-Grace
Cached
X-Cache-Expires
X-Time
SEOMOZ
X-BackendServer
X-Akamai-Edgescape
X-Avg-Cookie-Expires
X-AVG-Country-Code
X-Redman-Backend
X-SERVER-NAME
X-Cache-Only-Varnish
X-Drectory-Script
X-Processing-Time
Url
MJ12bot
X-Frontend
X-BKSrc
X-Remote-Addr
X-Varnish-Retries
X-Hit-Cache
X-Cache-Control
X-Redman-Final-Url
Qs-Cache
X-LP
X-Config-Blacklist-Version
X-Service-Id
X-CF-Passed-Proto
Accept-Charset
X-CB-Server
X-Pagename
Adm-Server
ServerID
X-High-Performance
SHInfo
X-Storage
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
X-Atraveo-ETag
X-Atraveo-Cache-Control
X-PRAM
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
X-Source-ID
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
X-Atraveo-TTL
X-Force
X-HeBS-Cache-Status
X-Hstore
VServer
X-Cache-Dispatchercachecontrol
X-Hrouter
X-FastCGI-Cache
Content-Encoding-Handler
X-Discourse-Route
X-Cache-Dispatcherpragma
X-Content-Security-Policy-Report-Only
X-Hiawatha-Cache
Eomportal-Instance
X-Amz-Storage-Class
X-GeoIP-Country-Name
X-GeoIP-Country-Code
X-Cookie-Domain
X-Country-Code
X-Varnish-Debug-TTL
X-Consent-Required
CDN-Uid
From-Origin
Tracecode
CDN-PullZone
CDN-CachedAt
X-HTML-Minification-Powered-By
,
X-Browser
X-Forwarded-Host
X-Amzn-RequestId
X-Amzn-Trace-Id
X-Varnish-Debug-Age
X-Amz-Apigw-Id
X-Symfony-Cache
X-LB-Server
X-RealServer
X-Request-Uri
CDN-RequestId
HCVer
X-CAPServer
X-Origin-Name
Edit
SRV
X-HydroSheep
HAVer
X-FORWARDED-PROTO
X-Envoy-Upstream-Service-Time
X-Resource
X-Stage
If-Modified-Since
Node
X-Cf-Powered-By
X-Svr-Proxy
X-SVR-IIS
X-AEM
X-Worker
X-Yottaa-Optimizations
X-Cache-Varnish
X-Span
Serverid
X-Smartcache-Timeout
X-Smartcache-Keys
X-Plat
X-Key
X-Yottaa-Metrics
X-JG-Page-Cache
X-Garden-Version
X-App-Server
X-Webkit-CSP
X-LW-Web-Server
X-SP-UniqueName
X-Role
Backend
Use-Proxy
RN-Server
X-Server-Addr
Machine
X-Scheme
X-Unique-Id
X-SP-Farm
Upgrade-Insecure-Requests
Report-To
X-Id
X-Directory-Script
Backend-Timing
X-Balanceador
X-Debug-Token
X-GeoIP
X-Analytics
Request-Country
Nitro-Cache
X-WP
Lb
Request-EU
Swift-Performance
X-AOL-HN
From
AR-PoweredBy
AR-SID
X-Actindo-Rs
IBM-Web2-Location
MW-Webserver
X-Autoru-App-Id
X-Actindo-Thread-Id
X-Autoru-Host
N365rili
X-7d-Instance-Id
X-Proxy-Skip
X-Sedo-Request-Id
Server-ID
X-Actindo-Request-Id
X-FireWall-Port
X-Distributor
RequestId
X-Akamai-Transformed
X-WPL-DATA
X-Desc
X-7d-Trace-Id
X-Clx-Request
X-FIRSTBase
X-Cache-Miss-From
Access-Control-Allow-Header
AR-ATIME
X-FPC
X-Rebelmouse-Cache-Control
X-Nx-All
X-Nx
X-IP
X-MSU-SOURCE
AR-CACHE
X-VCS-Cacheable
Locale
X-Streams-Distribution
Environment
X-Varnish-Ttl
X-Wikidot-Backend
X-NginX-Server
Resin-Trace
X-Oracle-Dms-Ecid
X-AF-Userserver
X-ACCELERATE
X-4ormat-Cacheable
X-Wikidot-Static-Cache
Fastly-Backend-Name
X-Client-Vid
X-Client-Image-Vid
X-EPiphany-Vid
X-Fstrz
X-Protected-By
X-Backend-Status
X-SAPP
Fastly-Restarts
X-ServerID
Xc-Version
ScoreTracker
Prama
Ohc-Response-Time
X-IIJ-Cache
X-Highwire-SessionId
X-PHP-Response-Code
X-VCS-Ttl
X-Response
X-Highwire-RequestId
X-GeoIP-Country
X-Cache-On
X-Cocoon-Version
X-CRA-DC
IISExport
HitType
X-SmartBan-Host
Accept-Encoding
Accept-Language
Filters
X-Client-Id
XX
X-Varnish-Hostname
X-SmartBan-URL
X-Resolver-IP
X-UA-Bot
X-Varnish-Action
X-Amz-Meta-S3b-Last-Modified
Disablevcache
Aurora-Node
X-Storage-Cache
X-Soro
X-DataDome
Srv-Name
X-Content-Encoded-By
X-Instance-Id
X-Storage-Cache-Date
X-Origin-Date
X-RiS-UFDI
*
X-Via-S
X-Storage-Cache-Expires
X-Cache-Var-Map
X-Cache-Var
ClientIP
X-NginX-Upstream
Gzip
F5-IpCliente
Drupal-Pagecache-Memcache
MC
CacheControlHeader
VSID
ViewMode
SVR
HitInfo
X-Proxy-Cache-Control
X-Server-IP
X-Ms-Request-Id
Paypal-Debug-Id
X-Adnet
X-Origin
FRONT-END-SECUREBROWSER
Edgecast
X-Amzn-Remapped-Content-Length
AMP-Redirect-To
VANITY-HOST
X-RENDER-TIME
X-Rack-Cors
X-Oracle-DMS-ECID
X-Session-ID
X-UUID
Cmsid
X-Webstats-RespID
X-TB-M
X-Via-NSCOPI
Cmstype
X-WEBMGR-CACHE
X-Distil-CS
TYPO3-Pid
X-ReqId
X-RequestId
TYPO3-Sitename
PagesDisplayed
X-Proto
DNNOutputCache
X-PROCESSED-BY
Provider
Cf-Ipcountry
X-SDE-Name
X-Mobilized-By
X-Cache-Ttl
AMP-Access-Control-Allow-Source-Origin
X-Reflector-Cache
X-Hosting-Env
AsisCache
X-Cdn-Forward
Server-Ip
X-Reflector
X-Clara-ASAP
X-Cache-Via
X-Req-Head-Response
X-Rule
X-Page-Cacheable
X-Cache-Time
X-NodeID
X-Info
X-Nginx-Page-Cache
X-Instance-Name
X-PM-ID
X-Nginx-Request-Processing-Time
X-Machine
X-Instance
X-Generated-Time
X-LAKANA-AB
X-PressLabs-Stats
X-NWS-UUID-VERIFY
X-Debounce
X-Route
NZSpeedy
MachineName
X-ProcessESI
Origin-Cache-Control
Page-Template
Origin-Edge-Control
Cm-Server
CD5
X-VC-Cache
X-Varnish-Grace
Yoncu-Errno
A-Powered-By
Actual-Object-TTL
X-UnsetCookies
Returned-Status
X-Search-Id
X-Purge-URL
X-ASAP-Age
X-Purge-Host
X-ASAP-Cache
X-Src-Webcache
X-TNCMS-Bot-Tier
SB-Cache-Remaining
SB-Cache-Life
SB-Site-Device
SB-Site-IE-VERSION
X-Runtime-Memory
X-Cache-Doesi
DeleGate-Ver
X-Pantheon-Phpreq
X-Pantheon-Site
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-Pantheon-Environment
X-Nginx-Host
X-Pantheon-Az
X-Ms-Version
X-Ruxit-Js-Agent
X-Secret
X-Beluga-Response-Time-X
X-Beluga-Response-Time
X-Upstream-Backend
X-Beluga-Status
X-Beluga-Trace
X-Serverid
X-Title
X-Built-By
X-Layout
X-Origin-Server
X-Airee-Node
X-Cacheable-TTL
X-VHOST
X-Who
Surrogate-Key-Raw
Pics-Label
Custom-Header
Access-Control-Allow-Method
X-Depends
X-VC-TTL
X-Gannett-Site-Version
X-Proxy-Cache-Key
X-PBY
X-SCM-Server-Number
X-Ssl-Cipher
X-VC-Enabled
X-UD-METHOD
X-Upstream-Status
X-Beluga-Record
X-Zendesk-User-Id
X-Zendesk-Origin-Server
X-Flex-Tag
X-Flex-Lastmod
Bios
X-Flex-Evstart
X-Flex-Lang
Disp
X-Flex-Tags
X-Map-Context
X-Server-Generated
X-Serv
X-RemovedCookies
X-Status
X-Svr
X-User-Agent-Tier
X-Timestamp
X-Flex-Evend
X-Flex-Community
X-Archive-Orig-Date
X-Archive-Orig-Content-Type
X-Archive-Orig-Connection
X-Varnish-Cache-Ttl
X-Archive-Orig-Last-Modified
X-Beluga-Node
X-Beluga-Cache-Status
X-Archive-Orig-Server
X-Archive-Guessed-Charset
X-AMAZEEIO
NLCacheNote
Memento-Datetime
Magicmarker
NEL
Beyond-Iis
X-WebKit-CSP-Report-Only
X-Yadis-Location
X-Redir-Url
TP-L2-Cache
X-Agent
WP-AdvCache-MemCached
TP-Cache
SERVER-NAME
X-Cluster
X-Compressed-By
X-Nbs
X-MAT-GEO
X-Geo-IP
Max-Age
X-VC-Cacheable
X-Cache-CFC
Web-Server
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Cache-Handler
X-Container
X-Varnish-Backend
X-Magnolia-Registration
X-Dw-Trace-Id
X-Skip-Cache
X-Sys-Req-ID
X-Twitter-Response-Tags
X-Transaction
X-SilverStripe-Cache
X-Sid
Cache-Ctrol
Content
Firespring-Website-Id
FindLaw
Copyright
X-Lb
X-Geo
X-Box
D
X-Upgrade-Enabled
X-Cache-Action
X-Cache-Extended
X-ENV
X-Connection-Hash
X-Compress-Hint
Cache-Cookie-Set-From
X-WebNode
Hummingbird-Cache
Dis-Env
AKA-DEVICE
AETN-State-Code
NB-Cache
Nginx-Cache
ProxiaInstanceId
Pramga
NODE
AETN-Postal-Code
AETN-Longitude
AETN-Continent-Code
AETN-City
AETN-Area-Code
Access-Control-Request-Headers
AETN-Country-Code
AETN-Country-Name
AETN-Latitude
AETN-EU
AETN-DEVICE
Session-Id
VC-NoCache
X-PBS-Appsvrname
X-PBS-Appsvrip
X-MyName
X-Middleton-Pagespeed
X-PBS-Fwsrvname
X-Provisioner-Version
X-Varnish-Hits
X-UPSTREAM-Address
X-Static
X-MCB-Server
X-GSL-Server
X-Cache-FS-Status
X-Blog
X-Avvio-Cms-Cacheload
X-CacheID
X-Catalyst
X-DynamicCache
X-Domain-Checked
X-Dispatcher-Number
Nd
Requested-Host
X-Nitro-Cache
X-MCF-ID
X-Jcms-Ajax-Id
X-Fpc
X-Page
X-Refresh
X-Varnish-Cached
X-UPServer
X-Sn-Servicetimems
X-EC2-Instance-Id
X-DevSrv-CMS
X-Bcwwwid
X-Batcache-Reason
X-Batcache
X-B3-Sampled
X-Built-With
X-Cache-Date
X-Cms
X-Cdn-Origin
X-Captured
X-Varnish-Cached-TTL
Arrnode
X-Cache-TTL-Current
X-Cache-TTL-Age
X-Cache-Me-Harder
X-Amz-Meta-Content-Md5
X-Ghost-Cache-Status
X-Goog-Meta-Policy
X-HTTPS-Cipher
X-Hit
X-Goog-Meta-Replace
Verto-Server
StatusCode
Httpd-Identifier
DrivedBy
Debug-Status
Id
IM-Version
ServerTokens
ServerSignature
NtCoent-Length
Request-Time
Og
X-E
X-DDM-SERVER-UPDATED
X-DDM-SERVER
X-ClientSide-Caching
X-Location
X-M-Log
X-Proxy-Id
X-Policy
X-M-Reqid
X-Bip
X-AppServer-Status
UrlWatchModule-Time
Thanks
SS
SBSS
Webserver
X-A
X-AppServer-Cache-Rule
X-AppServer-Cache-Exception
X-App-Runtime
X-Qnm-Cache
X-Rocket-Nginx-File
Description
DB-Nickname
Content-Sn
Backend-Powered-By
GD-Server
IES-Server
ModuleCacheType
Load-Balancer
Keywords
Xc
X-VG-WebCache
X-SE-Debug
X-Runtime-Affili
X-Rocket-Nginx-Reason
X-Session-Reinit
X-SID
X-Time-Microsecs
X-SuperCache
X-SSLTerm-Server
X-HTTPS-Protocol